Live data from Hacker News

Why Online Voting Is a Danger to Democracy

engineering.stanford.edu

131–140 of 316 posts

Re: Why Online Voting Is a Danger to Democracy

#131

Not convinced that in an age where I can buy a plane ticket for thousands of dollars, where we are thinking of sending people to Mars and I can securely communicate with people, in age where Edward Snowden is able to send private documents or whatev, and I have computers on my wrist, pocket and dick, I have to go to a physical place, stand in a queue and draw on a piece of paper to cast a ballot. I've been hearing th…

There are many problems. Is the hardware open-sourced, too? It should, there are known back-doors in many hardware nowadays (not talking about the unknown). Plane ticket, electronic banking, etc. - they have an immediate feedback that corrects mistakes (or worse, attacks), elections should not have such feedback, because one should not be able to prove how they voted afterwards (because of buying votes or coercion to…

"How do you "see" that you have voted for your choice? Because you monitor tells you so?"

Blockchain-like technology can do that for you.

(Not evertbody will have enough determination to actually do the checking, but some people will, and they'll alert general populace if something goes weird)

Re: Why Online Voting Is a Danger to Democracy

#132
post #129

Earlier quoted context omitted.

Wow, this is a rather… childish response. It doesn't actually rebut the claims being made, they seem to dismiss everything with “so what”, as if they do not actually understand what is wrong. And the rest of the post is just deflection by making ad hominems, or complaining about things that weren't what the researchers said. For example: > 1. Debian Linux packages were downloaded from a place that the experts didn’t…

They should have been downloaded over a secure connection That's not how apt works. The connection is assumed unreliable, the verification happens after download with the Debian keyring (already installed, and can be independently inspected and verified).

Sure, apt is secure. However, I don't think that's what's being discussed. If I remember correctly, the researchers were complaining about how Linux ISOs were downloaded, not packages. (The writer of the rebuttal seems to be confusing these, which is, again, concerning.) To quote their paper:

> Despite procedural safeguards, an attacker who strikes early enough can introduce malicious code into the counting server by using a chain of infections that parallels the configuration process. During pre-election setup, workers use a development machine, which is configured before setup begins, to burn Debian Linux installation ISOs to DVDs. These DVDs are later used to configure all election servers. If the machine used to burn them is compromised—say, by a dishonest insider, an APT-style attack on the development facility, or a supply-chain attack—the attacker can leverage this access to compromise election results.

> We experimented with a form of this attack to successfully change results in our mock election setup. We first created a modified Debian ISO containing vote-stealing malware intended to execute on the counting server. The tainted ISO is repackaged with padding to ensure that it is identical in size to the original. In a real attack, this malicious ISO could be delivered by malware running on the DVD burning computer, by poisoning the mirror it is retrieved from, or by a network-based man-in-the-middle.

> During the setup process, election workers check the SHA-256 hash of the ISO file against the SHA256SUMS file downloaded via anonymous FTP from debian.org. Since regular FTP does not provide cryptographic integrity checking, a network-based man-in-the-middle could substitute a hash that matched the malicious ISO. However, this hash would be publicly visible in videos of the setup process and might later arouse suspicion.

(https://jhalderm.com/pub/papers/ivoting-ccs14.pdf)

Re: Why Online Voting Is a Danger to Democracy

#133
post #104

The thing about online voting that has always gotten me is that it violates the ideals behind the "Australian Ballot." [0] ie, one should have the right to cast a secret ballot, and doing so in a public polling place at least theoretically guarantees this. With online elections, there is no proof or protection of this. For me that's the most important thing. Full Stop. Security implementations, hacking, etc. are all…

This is not an issue with online voting, and paper voting does not guarantee that right either. In Estonian e-voting, you can vote as many times as you want, only your last vote is counted. A week after online voting is closed, there is still a paper voting day, where you can go and override your online vote with a paper vote in the traditional booth. If you were coerced to vote a certain way online, you can still go…

In Estonian e-voting, you can vote as many times as you want, only your last vote is counted. A week after online voting is closed, there is still a paper voting day, where you can go and override your online vote with a paper vote in the traditional booth.

So they can unambiguously tie a specific vote to a voter, yet nobody is concerned about the possibilities of retribution against certain voters?

Re: Why Online Voting Is a Danger to Democracy

#134
post #119

Not convinced that in an age where I can buy a plane ticket for thousands of dollars, where we are thinking of sending people to Mars and I can securely communicate with people, in age where Edward Snowden is able to send private documents or whatev, and I have computers on my wrist, pocket and dick, I have to go to a physical place, stand in a queue and draw on a piece of paper to cast a ballot. I've been hearing th…

With all due respect, buying plane tickets and voting are quite different processes; when buying a ticket, everybody has an interest in knowing WHO you are, being able to connect your ticket with your credit card and whatnot. When you vote, we're very interested in NOT being able to connect you with your vote - heck, in some countries it can even be dangerous if the powers that be find out what you voted. (The result…

> My preferred voting mechanism would be a hybrid

This is the system advocated by Bruce Schneier[1], I wish it would get more traction. If it's good enough for him, it's good enough for me...

[1] https://www.schneier.com/essays/archives/2004/07/voting_secu...

Re: Why Online Voting Is a Danger to Democracy

#135

I just look at the state of internet "security" and that tells me all I need to know.

Can I assume you also have the expertise to comment on the physical security of current voting systems by comparison as well?

Yes, you can. Current voting systems are completely open to the public and simple enough for the average person to understand.

Re: Why Online Voting Is a Danger to Democracy

#136
post #107

"No more taking time out of your workday to travel to a polling place only to stand in a long line." In Sweden, the voting is always scheduled for Saturdays - to interfere as little as possible with peoples work. (Some work on Saturdays..)

And in recent elections some polling places have been open for weeks in advance so you don't have to vote on a specific day.

Re: Why Online Voting Is a Danger to Democracy

#137
post #12

The biggest problem with online/computerised voting is that it is a single point of attack for malicious actors. Even the best software security gets broken from time to time, online voting would allow zero-day attacks on elections - an absolute disaster. Whilst standard paper voting may also be subject to fraud, it takes the manipulation of thousands of people in order to alter ballots across a whole country. Comput…

My biggest worry isn't about software security. My worry about online remote voting is What is to stop physical coercion of the voter? When you have to gather at a centralised polling point to anonymously vote you can be damn sure no one is standing over the voter's shoulder twisting their arm while they vote. If you are voting remotely via a computer screen who is to know?

[deleted]

Re: Why Online Voting Is a Danger to Democracy

#138
post #87
post #37

Earlier quoted context omitted.

> However, it isn't really realistic to do re-counts right now, nor do people do them regularly. Australia uses paper ballots, and every election there's a seat or two somewhere that there's a recount. The major parties get their volunteers[0] to scrutinise the officials as they count as well, so you have multiple opposing interests scrutinising the actual count. Every vote basically gets at least three pairs of eyeb…

Italy here, it works in the same way. Parties have their watchers. I expect this to happen in every country, unless there is only one real party and the others are there just for the show. In every paper based system problems can arise outside the voting site: parties can buy votes but that's the same with internet voting. With the internet and computers an attacker has the benefit of changing a vote every 1,000, on…

The paper based system guards against vote buying through the guarantee of secrecy. I go into a booth on my own, make my mark(s) fold my paper, and put it in a locked box. No one but me knows how I voted.

If I go in with someone else, the officials will take action.

You can try to buy my vote, but I can just take your money and vote however I want.

If I can vote from wherever I like, then someone can stand over my shoulder and watch me vote, then only pay for it if I do as I'm told.

Re: Why Online Voting Is a Danger to Democracy

#139
I do think online voting is not a technology question and discussing implementation details is a red herring / bike shedding situation.

I see no incentive in disrupting the status quo and engaging more people in politics from the POV of the current ruling powers benefiting, yet there is a slippery slope argument for more decentralized/direct governing and less powermongering further down the road.

Re: Why Online Voting Is a Danger to Democracy

#140
post #48

The key claim is: there’s no way with any reasonable amount of resources that you can guarantee that the software and hardware are bug-free and that they haven’t been maliciously attacked The same could be said about other electronic systems that already govern lives, like planes, cars, phones and medical equipment. And yet life goes on.

Except half the country is not doing everything possible to bring every plane under their control. With the the other half trying to resit with little regard for the safety of the passengers. Security and transparency is far more important when humans are in conflict.
Post reply on HN